diff --git a/.github/workflows/python_package_test.yml b/.github/workflows/python_package_test.yml index 8bf8a10..cb5576f 100644 --- a/.github/workflows/python_package_test.yml +++ b/.github/workflows/python_package_test.yml @@ -163,7 +163,7 @@ jobs: - name: Upload Trivy scan results to GitHub Security tab # Do not upload SARIF reports on private repos - GitHub Advanced Security is not enabled if: ${{ !cancelled() && inputs.enable_trivy && !github.event.repository.private }} - uses: github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 #v3.28.0 + uses: github/codeql-action/upload-sarif@17a820bf2e43b47be2c72b39cc905417bc1ab6d0 #v3.28.6 with: sarif_file: "trivy-results.sarif" category: trivy